N8N · N8N · CVE-2026-56350
**Name of the Vulnerable Software and Affected Versions**
n8n versions prior to 2.8.0
**Description**
An authentication bypass exists that allows authenticated Single Sign-On (SSO) users to disable SSO enforcement via the API. This allows attackers to create local password credentials to authenticate directly, which bypasses organizational SSO policies and multi-factor authentication enforced by the identity provider.
**Recommendations**
Update to version 2.8.0 or later.